This Week in Cyber: October 1–7, 2026

Federal cyber funding, municipal ransomware, and new industrial security research led this week's developments. DOE announced $100 million for smaller electric utilities, while new findings from Claroty highlighted the financial and operational consequences of cyberattacks.


DOE Announces $100 Million for Utility Cybersecurity

The Department of Energy announced $100 million in cybersecurity technical assistance for electric cooperatives, municipal utilities, and small investor-owned utilities. Nonprofit applicants must partner with at least six qualifying utilities to deliver cybersecurity assessments, technologies, training, and related support.

Why it matters: The opportunity builds on the $250 million Rural and Municipal Utility Cybersecurity program established under the Bipartisan Infrastructure Law. Applications close October 20, creating a near-term funding opportunity for organizations supporting smaller electric utilities.


Congress Introduces Critical Infrastructure Security Bill

The bipartisan Securing Our Critical Infrastructure Act (H.R. 10671) was introduced to reauthorize a CISA program focused on security vulnerability warnings. The bill was referred to the House Homeland Security Committee.

Why it matters: Alongside DOE's utility funding announcement, the bill reflects two federal efforts to support smaller infrastructure operators: expanding access to cybersecurity resources and improving vulnerability notifications. The legislation has not yet advanced beyond committee referral.


Ransomware Disrupts Mississippi City Systems

The City of Vicksburg, Mississippi, disclosed a ransomware attack that forced municipal computer systems offline. Utility payments were disrupted, although 911, police, fire, and utility operations remained functional.

Why it matters: The incident resembles the IT disruption disclosed by Colorado's Sangre de Cristo Electric the following day. Both demonstrate how cyberattacks can interrupt customer-facing services without shutting down critical infrastructure operations.


Rockwell Reports Growing AI Investment in Manufacturing

Rockwell Automation's latest life sciences manufacturing research found that 90% of surveyed organizations consider digital transformation critical, 58% have deployed smart manufacturing technologies, and 45% plan to use AI or machine learning for cybersecurity. 

Why it matters: The findings complement Claroty's October 6 research showing that industrial security buyers increasingly consider AI a baseline requirement. Manufacturers are adopting connected technologies while reassessing how to secure their expanding operational environments.


Colorado Electric Cooperative Discloses Cyber Incident

Sangre de Cristo Electric Association reported suspicious activity in its IT network, prompting the cooperative to take servers offline. Billing and telephone services were temporarily disrupted, but electricity delivery and grid operations remained unaffected.

Why it matters: The incident followed DOE's $100 million announcement targeting cybersecurity assistance for smaller electric utilities. While unrelated to the funding decision, it illustrates the business-system disruptions that resource-constrained utilities must prepare to contain.


Claroty Finds 58% of Operators Experienced Cyberattacks Affecting Operations

Claroty's 2026 Global State of Operational Security report surveyed 2,000 business and technology leaders across more than 40 countries. Among respondents, 58% reported cyberattacks affecting operations over the previous year, with average incident-related losses of $1.04 million and three days of downtime.

Why it matters: The report provides broader context for the week's infrastructure incidents. It also found that 75% of respondents experienced operational incidents related to third-party access, while 49% reported limited or no monitoring of those connections. The findings identify third-party visibility as a continuing security gap.


ICS Cybersecurity Conference Opens in Nashville

The 2026 ICS Cybersecurity Conference opened October 6, bringing industrial operators, government agencies, and security providers together to discuss OT threats, industrial resilience, and connected control systems. CISA presented its CI Fortify initiative, focused on maintaining essential operations during severe communications disruptions.

Why it matters: CISA's emphasis on isolation exercises and recovery aligns with Claroty's new findings on operational downtime. Operators should expect greater attention to maintaining critical functions when external connectivity, vendor access, and remote support become unavailable.



State Policy Update: New Hampshire Establishes Cybersecurity Requirements for Water Systems

New Hampshire's SB 589, effective June 19, 2026, requires public water and wastewater systems using internet-connected control systems to maintain a cybersecurity protection program appropriate to their size and complexity. The New Hampshire Department of Environmental Services (NHDES) is developing implementation rules.

Why it matters: New Hampshire water and wastewater operators should determine whether their systems are covered, review their new cybersecurity obligations, and identify changes needed to meet the requirements. CrunchAtlas breaks down the law, affected systems, and implementation considerations.

Review the New Hampshire Water OT Security Requirements →


That's it for this week!

We'll be back next Thursday with the developments shaping critical infrastructure cybersecurity, operations and resilience.

Next
Next

This Week in Cyber: September 24 - 30, 2026